How to Find Files by Group Ownership in Ubuntu (find -group)

The Permission Audit

In Ubuntu Linux, every single file is owned by both a specific “user” and a specific “group.” While searching by user (-user) is common, auditing a system by group ownership is critical for security. For example, if you manage a shared web server, you might need to find every file owned by the www-data group to ensure that web scripts haven’t accidentally gained access to sensitive system directories, or you might need to locate all files owned by the docker group to verify container permissions. You must search the file system based on group IDs.

Using the find Command with -group

The Linux find command utilizes the -group flag to filter the search engine based exclusively on the assigned group ownership of the files.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the entire /var/ directory and return every file owned by the www-data group, type the following command exactly:
  3. sudo find /var/ -type f -group www-data
  4. Press Enter and provide your administrator password.

Targeting Orphaned Groups

Prefixing the command with sudo is mandatory to scan system directories where permissions might be restricted. If a user or group was recently deleted from the server, any files they previously owned will now display a raw numeric ID instead of a group name (creating “orphaned” files). To search for files owned by a specific numeric Group ID (GID) rather than a text name, simply use the -gid flag instead. For example, typing sudo find / -type f -gid 1005 will instantly locate every file owned by the deleted group, allowing you to quickly reassign them using the chown command.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.